▼
Allegations Only · No Settlement Yet
This article describes class action complaints. The statements below are unproven
allegations. NFM Lending, LLC has not been found liable, there is no certified class, and
nothing to claim at this time. This page is informational and is not legal advice.
NFM Lending, LLC, a residential mortgage lender headquartered in Linthicum, Maryland, has been hit with
at least five proposed class actions in the U.S. District Court for the District of Maryland. The first
was filed September 11, 2026, and the rest followed by September 17. Each one traces back to the same
event: a claim by the Interlock ransomware group, posted on or around September 7, 2026, that it had
broken into NFM's network and carried off more than 2.5 terabytes of data.
The two complaints OpenClassActions.com reviewed in full say that data includes borrowers' names,
Social Security numbers and financial information, and they accuse NFM of failing to train staff and
maintain reasonable safeguards. Those are allegations, and the data figures come from the attackers
themselves. NFM has acknowledged a cybersecurity incident but, according to
HousingWire's reporting,
has not said what was taken or how many people were affected. The cases are at the complaint stage, and
there is no settlement and nothing to claim.
Free settlement alerts
Get notified when new class actions open to claims
Join thousands of readers who get the latest class action settlements you may qualify for — delivered straight to your inbox.
Status
Complaints Filed · No Settlement
At least five proposed class actions in the District of Maryland, filed September 11–17, 2026
Data Allegedly Taken
Names, Social Security numbers, financial information
Per the Interlock ransomware claim cited in the complaints · not confirmed by NFM
People Affected
Not disclosed
No state attorney general breach notice located as of September 25, 2026
Can I Claim?
No — nothing to claim yet
NFM Lending originates home purchase and refinance loans, which means it collects the full set of
documents a mortgage application requires. The complaints describe NFM as holding that kind of personal
information for thousands of current and former clients, and the plaintiffs in both complaints reviewed
say they handed over their data as a condition of getting a mortgage.
On or around September 7, 2026, the Interlock ransomware group publicly claimed an attack on NFM
Lending. The complaints, citing a ransomware-tracking site's record of that claim, allege the group got into NFM's IT network and
extracted more than 2.5 terabytes of files containing names, Social Security numbers and financial
information. None of that has been confirmed by NFM, and a ransomware group's account of what it took
is not proof of what was actually exposed.
NFM's legal department acknowledged a cybersecurity incident in a statement reported by HousingWire and
said it could not confirm how many people were affected. It did not share further details.
Not as far as the public record shows. The complaint filed September 16 alleges NFM "has not yet begun
notifying its clients," and the September 11 complaint makes the same allegation. OpenClassActions.com
did not find an NFM Lending breach notice posted by a state attorney general's office as of
September 25, 2026, so there is no official count of affected people and no official list of exposed
data types yet.
That matters for anyone deciding what to do now. A breach notice is usually the first document that
says whose information was involved, and data breach settlements commonly require the ID or PIN printed
on it to file a claim online. If NFM sends one, keep it.
At least five complaints against NFM Lending, LLC were filed in the District of Maryland in the week
after the ransomware claim, according to federal docket records reported by HousingWire and the
complaints themselves:
• No. 1:26-cv-03607, filed September 11, 2026
• No. 1:26-cv-03627, filed September 14, 2026
• No. 1:26-cv-03632, filed September 14, 2026
• No. 1:26-cv-03661, filed September 16, 2026
• No. 1:26-cv-03677, filed September 17, 2026
The two complaints OpenClassActions.com read in full (Nos. 03607 and 03661) are close to word-for-word
matches. Both propose a nationwide class of everyone living in the United States whose private
information was compromised in the breach, and both plead the same four claims: negligence, breach of
implied contract, unjust enrichment and violation of the Maryland Consumer Protection Act. The case
captions and links to each docket are listed under Sources below.
No consolidation order had been located as of September 25, 2026. When several suits over the same
incident land in one court, they are commonly combined into a single case with interim lead counsel,
and that step would likely come before any response on the merits.
The complaints ask the court to certify the case as a class action and to award compensatory,
exemplary, punitive and statutory damages, restitution, declaratory and injunctive relief, and
attorneys' fees and costs. The harms alleged include time spent monitoring accounts, the lost value of
personal data, anxiety and stress, and a lasting risk of identity theft and fraud because Social
Security numbers cannot easily be changed. One complaint also asks the court to bar NFM from further
unfair or deceptive practices.
None of those requests has been granted, and NFM has not been found liable for anything.
The usual sequence in a multi-case breach litigation is a motion to consolidate and appoint interim
class counsel, a consolidated complaint, and then a motion to dismiss from the defendant. Many breach
cases settle, but some are dismissed and some take years; there is no way to say which path this one
will take. If a settlement is ever reached, class members would receive notice and a claim process
would open, and OpenClassActions.com will update this page.
Meanwhile, the
data breach notice guide
walks through what to do when Social Security numbers and financial account data are exposed, and the
data breach settlement tracker
lists breach settlements with open claim windows, including the
NJ Lenders settlement
from another mortgage lender's 2025 cyberattack.
Has NFM Lending confirmed a data breach?
NFM Lending's legal department acknowledged a cybersecurity incident in a statement reported by HousingWire, but it did not describe what data was involved and said it could not confirm how many people were affected. The 2.5 terabyte figure and the list of stolen data come from the Interlock ransomware group's own claim, which the complaints repeat on information and belief.
How do I know if my information was involved?
No one can say yet. The complaints filed through September 16, 2026 allege NFM had not started notifying customers, and OpenClassActions.com had not found an NFM Lending breach notice posted with a state attorney general as of September 25, 2026. People who took out or applied for a mortgage with NFM Lending should watch for a notification letter, which would describe what was exposed and any identity protection offered.
Do I need to hire a lawyer or join one of the lawsuits?
No. The cases are proposed class actions, so if a class is certified or a settlement is reached, members of the class would be covered without having filed their own suit. If a settlement is ever approved, class members would get notice explaining how to file a claim, opt out or object.
Why are there five separate lawsuits over one breach?
Different plaintiffs and law firms filed their own complaints within a week of the ransomware claim. When several suits in the same court describe the same incident, the court often consolidates them and appoints interim lead counsel for the proposed class. No consolidation order in the NFM Lending cases had been located as of September 25, 2026.
What should NFM Lending customers do now?
Consumer-protection agencies generally recommend placing a free credit freeze with Equifax, Experian and TransUnion, watching bank and mortgage accounts for unfamiliar activity, and being wary of calls or emails that reference a loan and ask for payment or personal details. Keep any breach notice NFM sends, because a future settlement may require an identifier printed on it.
• Class Action Complaint, Koppenhaver v. NFM Lending, LLC, No. 1:26-cv-03607 (D. Md. filed Sept. 11, 2026) — complaint PDF via CourtListener RECAP.
• Romancik v. NFM Lending LLC, No. 1:26-cv-03627 (D. Md. filed Sept. 14, 2026) — CourtListener docket.
• Clark v. NFM Lending, LLC, No. 1:26-cv-03632 (D. Md. filed Sept. 14, 2026) — Justia docket.
• Class Action Complaint, Smith v. NFM Lending, LLC, No. 1:26-cv-03661 (D. Md. filed Sept. 16, 2026) — complaint PDF via CourtListener RECAP.
• Richardson v. NFM Lending LLC, No. 1:26-cv-03677 (D. Md. filed Sept. 17, 2026) — CourtListener docket.
• HousingWire, "Interlock ransomware claim triggers lawsuit against NFM Lending" — case list and NFM's statement.
For more class actions keep scrolling below.
Status
Complaints filed · no settlement
Case Title
Koppenhaver v. NFM Lending, LLC (first-filed of at least five)
Case Number
1:26-cv-03607
Court
U.S. District Court, District of Maryland
Date Filed
September 11, 2026